The domain 1800dcdn.blob.core.windows.net registered by Microsoft Corporation was initially registered in August of 1995 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrant:
Microsoft Corporation
Registrar:
MARKMONITOR INC.
Server location:
Sao Paulo, Brazil (BR)
Create date:
Thursday, August 10, 1995
Expires date:
Saturday, June 4, 2016
Updated date:
Wednesday, October 8, 2014
ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.RICHMEDIASYSTEMS, PUP.RICHMEDIASYSTEMS.Installer (M), PUP.RICHMEDI.Installer (M)
95.65%
G Data
Win32.Adware.OpenCandy, Gen:Trojan.Heur.zu3@x44JrCfi
82.61%
McAfee
Artemis!C40FC4A0A9DA, Artemis!DCA9EBD92BA6, Artemis!7CCD61D90EA4, Artemis!8A67095D3FD0, Artemis!B3A72B5F066E, Artemis!5FBB974F98E8, Artemis!05A7A43330C9, Artemis!F145F2E0A5CA, Artemis!7800BE45D11B, Artemis!2D16AD524A40, Artemis!93465A896B71, Artemis!60D1A42B1C4F, Artemis!358B0EDCA703, Artemis!727BB0EFDEC3, Artemis!B2D8E94616EA, Artemis!8799C5904695, Artemis!23879AC4752E
82.61%
K7 AntiVirus
Trojan
80.43%
Trend Micro House Call
Suspici.F4CBE3E4, ADW_OpenCandy, Suspicious_GEN.F47V0313, TROJ_GEN.R02SH05CE15, TROJ_GEN.R02KH05CV15, Suspicious_GEN.F47V0327
80.43%
Malwarebytes
PUP.Optional.OpenCandy
78.26%
VIPRE Antivirus
Sevas-S Installer, Threat.4847482, Trojan.Win32.Generic
76.09%
Dr.Web
Adware.Downware.10304
76.09%
Agnitum Outpost
Riskware.Agent
71.74%
Clam AntiVirus
Win.Trojan.Agent-855157
71.74%
ESET NOD32
Win32/OpenCandy.C potentially unsafe (variant)
63.04%
AhnLab V3 Security
PUP/Win32.OpenCandy, PUP/Win32.Generic, PUP/Win32.Agent
54.35%
Sophos
Generic PUA HN, OpenCandy, PUA 'OpenCandy', Generic PUA NH, Generic PUA NC, Generic PUA CB
36.96%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
34.78%
The domain 1800dcdn.blob.core.windows.net has been seen to resolve to the following IP address.
blob.am3prdstr10a.store.core.windows.net
May 5, 2015
File downloads found at URLs served by 1800dcdn.blob.core.windows.net.
Latest 30 of 46 download URLs
The following 6 files have been seen to comunicate with 1800dcdn.blob.core.windows.net in live environments.
URL:
http://1800dcdn.blob.core.windows.net/
SSL certificate subject:
CN=*.blob.core.windows.net
SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Web server:
Microsoft-HTTPAPI/2.0
Related Domains